CVE-2025-2138

LOW

IBM Engineering Requirements Management Doors Next <7.1 - Privilege...

Title source: llm

Description

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security.

Scores

CVSS v3 3.5
EPSS 0.0004
EPSS Percentile 11.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-602
Status published

Affected Products (3)

ibm/engineering_requirements_management_doors_next
ibm/engineering_requirements_management_doors_next
ibm/engineering_requirements_management_doors_next

Timeline

Published Oct 12, 2025
Tracked Since Feb 18, 2026